首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 ETSI TS 119 101
到馆提醒
收藏跟踪
购买正版
Electronic Signatures and Infrastructures (ESI); Policy and security requirements for applications for signature creation and signature validation 电子签名和基础设施(ESI);签名创建和签名验证应用程序的策略和安全要求
发布日期: 2016-03-01
ETSI TS 119 101为签名创建应用程序提供了一般安全和策略要求, 验证和扩充。本文件主要涉及以下行为者:签名创建、签名验证和/或签名应用程序的实施者和提供者 扩充,世卫组织需要确保相关要求得到满足。集成签名创建、签名验证和/或签名增强应用程序的参与者 带有业务流程软件(或使用独立软件)的组件,他们希望确保 整个签名创建/验证/增强过程的功能,以及签名 创建/验证在足够安全的环境中完成。本文件适用于这些参与者及其评估者(用于自我评估或第三方评估) (第三方)有一份检查执行情况的标准清单。这些要求涵盖签名创建、签名验证和/或签名增强的应用,即 实施和提供签名创建/验证/增强应用模块 (SCA/SVA/SAA)、驱动应用程序(DA)、SCA和签名创建设备之间的通信 以及使用SCA/SVA/SAA的环境。它还规定了用户界面要求,同时 用户界面可以是SCA/SVA/SAA的一部分,也可以是调用SCA/SVA/SAA的DA的一部分。任何使用 业务流程中的SCA/SVA/SAA组件充当驱动应用程序的角色。该文件涵盖:法律驱动的政策要求。信息安全(管理体系)要求。签名创建、签名验证和签名增强过程要求。 开发和编码策略要求。一般要求。签名创建应用程序和签名验证应用程序的保护配置文件(PP)不在范围内,并且 在CEN标准“签名创建和验证应用的保护配置文件”[i.9]中定义。 信托服务提供商的一般要求见ETSI EN 319 401[i.24]。信托服务的要求 提供签名创建或验证服务的提供商不在范围之内。对信托服务提供者的要求 提供签名创建服务的定义见ETSI TS 119 431[i.22],CEN EN 419 241[i.21]定义 对远程签名创建设备的要求。对提供签名的信托服务提供商的要求 验证服务的定义见ETSI TS 119 441[i.23]。
ETSI TS 119 101 provides general security and policy requirements for applications for signature creation, validation and augmentation.The present document is primarily relevant to the following actors:Implementers and providers of applications for signature creation, signature validation and/or signature augmentation, who need to ensure that relevant requirements are covered.Actors that integrate applications for signature creation, signature validation and/or signature augmentation components with business process software (or use standalone software), who want to ensure proper functioning of the overall signature creation/validation/augmentation process and that the signature creation/validation is done in a sufficiently secure environment.The present document is applicable to these actors, and their evaluators (for a self-evaluation or an evaluation by a third party) to have a list of criteria against which to check the implementation.The requirements cover applications for signature creation, signature validation and/or signature augmentation, i.e. the implementation and provision of the Signature Creation/Validation/Augmentation Application modules (SCA/SVA/SAA), the driving application (DA), the communication between the SCA and the signature creation device (SCDev) and the environment in which the SCA/SVA/SAA is used. It also specifies user interface requirements, while the user interface can be part of the SCA/SVA/SAA or of the DA which calls the SCA/SVA/SAA. Any entity using SCA/SVA/SAA components in its business process acts as driving application.The document covers:Legal driven policy requirements.Information security (management system) requirements.Signature creation, signature validation and signature augmentation processes requirements.Development and coding policy requirements.General requirements.Protection Profiles (PP) for signature creation applications and signature validation applications are out of scope and are defined in the CEN standard "Protection Profiles for Signature Creation & Validation Applications" [i.9]. General requirements for trust service providers are provided in ETSI EN 319 401 [i.24]. Requirements for trust service providers providing signature creation or validation services are out of scope. Requirements on trust service providers providing signature creation services are to be defined in ETSI TS 119 431 [i.22], with CEN EN 419 241 [i.21] defining requirements for a remote signature creation device. Requirements on trust service providers providing signature validation services are to be defined in ETSI TS 119 441 [i.23].
分类信息
关联关系
研制信息
相似标准/计划/法规
现行
ETSI TS 102 853
Electronic Signatures and Infrastructures (ESI); Signature validation procedures and policies
电子签名和基础设施(ESI);签名验证程序和政策
2014-12-01
现行
ETSI TS 119 172-2
Electronic Signatures and Infrastructures (ESI); Signature Policies; Part 2: XML format for signature policies
电子签名和基础设施(ESI);签名政策;第2部分:签名策略的XML格式
2019-12-01
现行
ETSI TS 119 172-3
Electronic Signatures and Infrastructures (ESI); Signature Policies; Part 3: ASN.1 format for signature policies
电子签名和基础设施(ESI);签名政策;第三部分:ASN 1签名策略的格式
2019-12-01
现行
ETSI TS 119 441
Electronic Signatures and Infrastructures (ESI); Policy requirements for TSP providing signature validation services
电子签名和基础设施(ESI);TSP提供签名验证服务的策略要求
2018-08-01
现行
ETSI EN 319 421
Electronic Signatures and Infrastructures (ESI); Policy and Security Requirements for Trust Service Providers issuing Time-Stamps
电子签名和基础设施(ESI);信托服务提供商发行时间戳的政策和安全要求
2016-03-01
现行
ETSI TS 119 172-1
Electronic Signatures and Infrastructures (ESI); Signature Policies; Part 1: Building blocks and table of contents for human readable signature policy documents
电子签名和基础设施(ESI);签名政策;第1部分:人类可读签名政策文件的构建块和目录
2015-07-01
现行
ETSI TS 101 456
Electronic Signatures and Infrastructures (ESI); Policy requirements for certification authorities issuing qualified certificates
电子签名和基础设施(ESI);颁发合格证书的认证机构的政策要求
2007-05-01
现行
ETSI TS 119 511
Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers providing long-term preservation of digital signatures or general data using digital signature techniques
电子签名和基础设施(ESI);对使用数字签名技术长期保存数字签名或一般数据的信托服务提供商的政策和安全要求
2019-06-01
现行
ETSI TS 102 573
Electronic Signatures and Infrastructures (ESI); Policy requirements for trust service providers signing and/or storing data objects
电子签名和基础设施(ESI);信任服务提供商签署和/或存储数据对象的策略要求
2012-04-01
现行
ETSI TS 119 431-2
Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers; Part 2: TSP service components supporting AdES digital signature creation
电子签名和基础设施(ESI);信托服务提供商的政策和安全要求;第2部分:支持数字签名创建的TSP服务组件
2018-12-01
现行
ETSI TR 101 533-2
Electronic Signatures and Infrastructures (ESI); Data Preservation Systems Security; Part 2: Guidelines for Assessors
电子签名和基础设施(ESI);数据保存系统安全;第2部分:评估员指南
2012-04-01
现行
ETSI TS 119 431-1
Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers; Part 1: TSP service components operating a remote QSCD / SCDev
电子签名和基础设施(ESI);信托服务提供商的政策和安全要求;第1部分:运行远程QSCD/SCDev的TSP服务组件
2018-12-01
现行
ETSI TS 102 158
Electronic Signatures and Infrastructures (ESI); Policy requirements for Certification Service Providers issuing attribute certificates usable with Qualified certificates
电子签名和基础设施(ESI);颁发可与合格证书一起使用的属性证书的认证服务提供商的政策要求
2003-10-01
现行
ETSI TS 101 533-1
Electronic Signatures and Infrastructures (ESI); Data Preservation Systems Security; Part 1: Requirements for Implementation and Management
电子签名和基础设施(ESI);数据保存系统安全;第1部分:实施和管理要求
2012-04-01
现行
DIN EN 319421
Electronic Signatures and Infrastructures (ESI) - Policy and Security Requirements for Trust Service Providers issuing Time-Stamps (Endorsement of the English version EN 319 421 V1.1. (2016-03) as German standard)
电子签名和基础设施(ESI).发行时间戳的信托服务提供商的政策和安全要求(作为德国标准认可英文版EN 319 421 V1.1.(2016-03)
2016-08-01
现行
ETSI TS 119 495
Electronic Signatures and Infrastructures (ESI); Sector Specific Requirements; Qualified Certificate Profiles and TSP Policy Requirements under the payment services Directive (EU) 2015/2366
电子签名和基础设施(ESI);特定行业的要求;支付服务指令(EU)2015/2366下的合格证书配置文件和TSP政策要求
2019-11-01
现行
ETSI TR 119 411-4
Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 4: Checklist supporting audit of TSP against ETSI EN 319 411-1 or ETSI EN 319 411-2
电子签名和基础设施(ESI);信托服务提供商颁发证书的政策和安全要求;第4部分:根据ETSI EN 319 411-1或ETSI EN 319 411-2支持TSP审计的检查表
2018-05-01